Skip to content

ci: pin GitHub Actions to commit SHAs - #1204

Closed
chopmob-cloud wants to merge 1 commit into
a2aproject:mainfrom
chopmob-cloud:ci/pin-actions-sha
Closed

chopmob-cloud wants to merge 1 commit into
a2aproject:mainfrom
chopmob-cloud:ci/pin-actions-sha

Conversation

@chopmob-cloud

Copy link
Copy Markdown
Contributor

Pins the GitHub Actions in .github/workflows to full-length commit SHAs with # vX version comments, bringing this repo in line with the sibling repo a2a-go, which is already fully pinned.

Why

A mutable tag like @v7 can be moved to new code after review, so a compromised or hijacked action tag would run with this workflow's permissions. Pinning to a commit SHA is the OpenSSF Scorecard "Pinned-Dependencies" control and the GitHub-recommended practice. This repo already runs Dependabot for the github-actions ecosystem, so Dependabot keeps the SHA pins current (it bumps the SHA and the # vX comment together).

What

  • Pins every non-local uses: across 16 workflow files to its exact commit SHA, keeping a # vX version comment. Same versions, no upgrades or downgrades.
  • Generated with pinact; each pinned SHA was verified to resolve to the version in its comment via the GitHub API.
  • The diff is large but purely mechanical: ref-pinning only, no job, step, trigger, or permission changed, so there is no functional change.

Pin the GitHub Actions in .github/workflows to full-length commit SHAs
with version comments. A mutable tag can be re-pointed after review, so
pinning to a commit SHA is the OpenSSF Scorecard Pinned-Dependencies
control. Ref-pinning only, same versions, no functional change. Generated
with pinact; each SHA verified to resolve to its version tag.

Signed-off-by: AlgoVoi <chopmob@gmail.com>
@ehsavoie

ehsavoie commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

I'm not really convinced by the value of pinning official github actions: while I can understand this in some professional hardened environment, I think given the high rate of evolution of this project we should stay on the edge.

@kabir

kabir commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

+1 I also think this is overkill for the official GH Actions

@kabir kabir closed this Oct 6, 2026
@chopmob-cloud

Copy link
Copy Markdown
Contributor Author

Not a problem at all, and thanks for the consideration. Completely understand the call for first-party actions in a fast-moving project. Appreciate you both taking the time to look.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants